PostgreSQL doesn't support parameterizing table or column names - you'll have to either concatenate these in into your string (but beware of SQL injection), or write a plpgsql. See http://stackoverflow.com/a/13289939/640325 for an example.

Regardless, concatenating in the values from your datagrid leaves you wide open to SQL injection, consider using parameters there.